CVE-2026-78575
published 2026-09-10CVE-2026-78575: IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line…
PriorityP264high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.79%
54.8th percentile
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | langflow_oss | 1.0.0 – 1.11.5 | — |
| langflow | langflow | >= 1.0.0 < 1.11.6 | 1.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Langflow OSS up to 1.11.5 MCP stdio server command injection
vuldb·2026-09-11·CVSS 8.8
CVE-2026-78575 [HIGH] IBM Langflow OSS up to 1.11.5 MCP stdio server command injection
A vulnerability has been found in IBM Langflow OSS up to 1.11.5 and classified as critical. The affected element is an unknown function of the component MCP stdio server. This manipulation causes command injection.
This vulnerability is registered as CVE-2026-78575. Remote exploitation of the attack is possible. No exploit is available.
GHSA
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configurati
ghsa_unreviewed·2026-09-11
CVE-2026-78575 [HIGH] CWE-78 IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configurati
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-10
Published